← Back

CVE-2025-36005

nvd nist
Published: Jul 24, 2025Modified: Aug 22, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same hostname and port due to improper certificate validation.

Affected (58)

2 products
Mq Operator
Configuration A
58 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 3.5.1 to 3.6.0
From 2.0.0 to 2.0.29
From 3.2.0 to 3.2.13
Version 3.3.0
Version 3.4.0
Version 3.4.1
Version 3.5.0
Ibm
Version 9.3.0.0 r1
Version 9.3.0.0 r2
Version 9.3.0.0 r3
Version 9.3.0.10 r1
Version 9.3.0.10 r2
Version 9.3.0.11 r1
Version 9.3.0.11 r2
Version 9.3.0.15 r1
Version 9.3.0.16 r1
Version 9.3.0.16 r2
Version 9.3.0.17 r1
Version 9.3.0.17 r2
Version 9.3.0.17 r3
Version 9.3.0.1 r1
Version 9.3.0.1 r2
Version 9.3.0.1 r3
Version 9.3.0.1 r4
Version 9.3.0.20 r1
Version 9.3.0.20 r2
Version 9.3.0.21 r1
Version 9.3.0.21 r2
Version 9.3.0.21 r3
Version 9.3.0.25 r1
Version 9.3.0.3 r1
Version 9.3.0.4 r1
Version 9.3.0.4 r2
Version 9.3.0.5 r1
Version 9.3.0.5 r2
Version 9.3.0.5 r3
Version 9.3.0.6 r1
Version 9.4.0.0 r1
Version 9.4.0.0 r2
Version 9.4.0.0 r3
Version 9.4.0.10 r1
Version 9.4.0.10 r2
Version 9.4.0.11 r1
Version 9.4.0.11 r2
Version 9.4.0.11 r3
Version 9.4.0.5 r1
Version 9.4.0.5 r2
Version 9.4.0.6 r1
Version 9.4.0.6 r2
Version 9.4.0.7 r1
Version 9.4.1.0 r1
Version 9.4.1.0 r2
Version 9.4.1.1 r1
Version 9.4.2.0 r1
Version 9.4.2.0 r2
Version 9.4.2.1 r1
Version 9.4.2.1 r2
Version 9.4.3.0 r1

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.